Skip to content
Docs menu: Anti-Nuke

Protection

Anti-Nuke

About this feature: Anti-Nuke

In short

Anti-Nuke stops someone wrecking your server. If one person deletes 3 channels or bans 5 people in a minute, or deletes 8 channels in an hour, Bastion quarantines them at once and tells you. A mix of smaller actions is caught too. It's on by default.

What a nuke is

A nuke is when someone with power wrecks a server: they delete the channels and roles and ban everyone. It's usually a hacked admin account, a staff member who's turned against you, or a malicious bot. It takes seconds.

Anti-Nuke cuts the attacker off after the first few actions, not after the server is gone.

Turn it on

It's already on. To check, open the dashboard and look at the Anti-Nuke card on the overview. The switch on the card turns it on or off. Only the server owner and trusted people can change Anti-Nuke.

The exact numbers are on the Anti-Nuke page under Advanced settings. Your security level already filled them in.

How it works

  1. Bastion watches the audit log

    Discord keeps a record of who did what, called the audit log. Bastion reads it to see who deleted a channel, who banned a member and so on.

  2. It counts per person, by the minute and by the hour

    Deleting one channel is normal. Deleting three in a minute isn't, and neither is eight in an hour. Each action has its own limit, with one number for a minute and one for an hour. Reaching either one counts. Bans, kicks and quarantines that a moderator makes with Bastion's commands are counted against that moderator, the same as ones done by hand. Timeouts are never counted here. Things Bastion does on its own aren't counted either.

  3. It stops whoever goes over

    By default the person is put in quarantine, which removes all their roles. A bot can't be quarantined, so a bot that goes over a limit is kicked. If you set the punishment to kick or ban, that's used instead.

  4. It tells you

    A message goes to your security log channel saying who, what and why, and a case is saved. If you chose alert roles on the Logs page, they're pinged. If Bastion couldn't stop the person because their role is above its own, it also messages the server owner directly.

The limits

Every limit has two numbers: how many in a minute, and how many in an hour. The minute number catches a fast attack, where someone deletes everything at once. The hour number catches a slow one, where someone spaces it out to stay under the minute number.

These are the Balanced defaults. In the dashboard, open Anti-Nuke, then Advanced settings, then Limits. Each row shows two numbers, a minute and an hour, and an on/off switch. A minute can be 1 to 60. An hour can be 1 to 500. Switching a row off switches off both numbers. Bastion steps in on the action that reaches either number, so 3 a minute stops the third delete in a minute, and 8 an hour stops the eighth in an hour.

SettingWhat it countsA minuteAn hour
Deleting channelsChannel deletes by one person.38
Creating channelsChannels created by one person.620
Deleting rolesRole deletes by one person.38
Creating rolesRoles created by one person.620
Banning membersBans by one person.516
Kicking membersKicks by one person. Quarantines made with Bastion's commands count here too. Timeouts don't.516
Creating webhooksWebhooks created by one person.310
Deleting webhooksWebhooks deleted by one person.38
Deleting emojiEmoji deleted by one person.515

Relaxed and Strict use different numbers. See the comparison in the setup guide.

Mixed attacks: the attack score

Limits count one kind of action each. Someone who deletes 2 channels and 2 roles has reached neither limit, but has clearly started wrecking the server.

So every action also has points. Deleting a channel is 25. Deleting a role is 25. Banning a member is 20. The points from every kind of action are added together for each person, and 100 points within ten minutes sets off Anti-Nuke. Two channel deletes and two role deletes make exactly 100.

The points are under Advanced settings, in the group Mixed attacks. The full list, with worked examples, is on the attack score page.

Bastion's own commands count too

When a moderator runs /ban or /kick, Discord's audit log shows Bastion as the one who did it. Bastion counts it against the moderator anyway, on the same counter as bans and kicks done by hand.

  • /ban counts towards Banning members.
  • /kick and /quarantine add count towards Kicking members. A quarantine counts as a kick, so the two share one counter.
  • /timeout doesn't count towards any Anti-Nuke limit. See Timeouts are separate, below.
  • A warn step that kicks or bans counts against the moderator who gave the warning.
  • Right-click actions count exactly like the slash commands.

The command that reaches the limit is refused. On Balanced the fifth ban in a minute doesn't happen, and neither does the sixteenth in an hour. The moderator is told which limit they reached, for example 5 kicks or quarantines a minute, or 16 bans an hour. They then get the punishment set below, and it's reported in your security log like any other anti-nuke catch.

Warnings on their own, /untimeout, /unban and approving an appeal aren't counted.

Timeouts are separate

No timeout counts towards the kick limit, and a timeout never gets a moderator punished. That covers /timeout, the right-click Timeout, the Timeout button on a member report, a warn step that times out, timeouts given by hand in Discord and Automod timeouts.

Timeouts made through Bastion have their own limit instead: 10 a minute for each moderator. Over that, the timeout is refused with a message and nothing else happens. Nobody is quarantined and nothing is reported. The number is fixed and applies even when Anti-Nuke is off. The owner and trusted people are exempt.

A timeout is mild and wears off. Without this rule, a few accounts misbehaving on purpose could get an honest moderator quarantined for dealing with them.

/purge has its own fixed limit of 5 uses a minute for each moderator. Going over is refused, not punished. See moderation.

Other settings

SettingWhat it doesDefault
PunishmentWhat happens to the person: quarantine, kick or ban.Quarantine
Block dangerous permissionsCatches three things: editing a role to add a dangerous permission, creating a role that already has one, and giving a role with one to another member. Bastion undoes the change and punishes whoever did it.On
Block dangerous channel permissionsCatches someone handing out powers through one channel's own permission settings. Bastion puts the channel back and punishes whoever did it. See Dangerous channel permissions, below.On
Keep quarantined people quarantinedIf someone frees a quarantined member by hand, or gives them a role, Bastion quarantines the member again and punishes whoever did it. See quarantine.On
Extra user IDsUnder Who can release quarantined people. Up to 10 people who may free a quarantined member by hand, besides the owner and trusted people.None
Protect the custom invite linkPunishes anyone but the owner or a trusted person who changes or removes your vanity URL. Discord doesn't let Bastion change the link back, so check it in Server Settings afterwards.On
Catch mass prunesTreats a prune that removes 5 or more members as an attack and punishes whoever ran it. The pruned members can't be brought back.On
Panic modeWhen an attack is caught, locks channels, takes powers off staff roles, pauses Bastion's moderation commands and recreates deleted roles and channels from your last backup. It ends by itself after 15 minutes. Pro. See panic mode.Off

Dangerous permissions

Dangerous permissions are Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, Ban Members, Kick Members and Mention @everyone. A common trick is to quietly add one of these to @everyone or a low role. With Block dangerous permissions on, Bastion catches three ways of handing out power:

What someone doesWhat Bastion does
Edits a role to add a dangerous permission.Puts the role's permissions back the way they were.
Creates a new role that already has a dangerous permission.Takes the dangerous permissions off the new role. If it can't, it deletes the role.
Gives a role with a dangerous permission to another member.Takes the role back off that member.

In each case the person who did it gets the punishment, and you get a report. The owner and trusted people can do all three freely.

For new roles and for roles being handed out, dangerous means powers beyond what @everyone already has. If @everyone can already mention everyone in your server, a role that also can is giving nobody anything new, so it's left alone. Someone taking a powerful role for themselves isn't counted here. Discord only lets people hand out roles below their own, so that's left to Discord's role order.

Dangerous channel permissions

Every channel has its own permission settings. An attacker can leave the roles alone and give @everyone Manage Webhooks in one quiet channel instead. Block dangerous channel permissions catches that.

It steps in when someone allows one of these in a channel's settings, for @everyone, a role or a single member:

  • Manage Channels
  • Manage Permissions
  • Manage Webhooks
  • Manage Messages
  • Manage Threads
  • Mention @everyone

Bastion puts the channel's permissions back the way they were. If the entry was new, it's removed. The person who made the change gets the punishment, and you get a report.

  • Giving a role or member a power they already have across the whole server is left alone. Nothing new was handed out.
  • Denying a permission, or taking one away, is left alone.
  • The owner and trusted people can change channel permissions freely.

TipLeave the punishment on Quarantine. It stops the person instantly and is easy to undo if it was a mistake. A ban isn't.

Who's never punished

The server owner and trusted people skip every limit. That's useful, and also a risk: if a trusted account is hacked, Bastion won't stop it. The same goes for Bastion's commands: the owner and trusted people can /ban and /kick without limit. Bastion never counts what it does on its own.

CarefulAnti-Nuke can only stop people ranked below Bastion. If an admin role sits above Bastion's role, Bastion can't touch them. All it can do is warn you in the log and message the owner. Keep Bastion at the top. See the setup guide.

Bastion quarantined one of my admins. Why?

They went over a limit, for example deleting three channels in a minute or eight in an hour while tidying up. The log says which, with the words in under a minute or within an hour. Check it, then run /quarantine remove to give their roles back.

I need to delete lots of channels. What do I do?

If you're the owner, go ahead. You're never punished. Otherwise ask the owner to do it. Going slowly doesn't help much, because the hour limit still counts.

A moderator was quarantined after using /ban.

They reached the ban limit using Bastion's commands, either the one for a minute or the one for an hour. Those count per moderator, the same as bans by hand. Run /quarantine remove if it was honest work, and raise Banning members if your staff need more room.

Can timing people out get a moderator quarantined?

No. Timeouts never count towards the kick limit. A moderator can time out 10 people a minute through Bastion. After that the timeout is refused with a message.

Bastion took a role off someone I just promoted.

The role has a dangerous permission and you aren't the owner or a trusted person. Ask the owner to give the role, or to add you to the trusted list.

A moderator was quarantined and the log says no single limit was reached.

Their actions added up to 100 points on the attack score within ten minutes. The log lists what they did. Run /quarantine remove if it was honest work.

Bastion undid a channel permission I set.

You allowed a powerful permission, such as Manage Messages, in one channel's settings, and you aren't the owner or a trusted person. Ask the owner to set it, or give the role that permission across the whole server if it should have it.

Someone was punished for taking the Quarantined role off a member.

Keep quarantined people quarantined is on. Use /quarantine remove to release someone. See quarantine.

Why did Bastion kick another bot?

That bot went over a limit. Ticket bots do this often because they create and delete channels all day. See troubleshooting.

Can it bring back deleted channels?

Not on its own. That needs a backup, which is a Pro feature. Anti-Nuke stops the damage early so there's less to bring back.

Anti-Nuke isn't doing anything.

Check Bastion's role is at the top and that it has View Audit Log. Run /status to see both.

Last updated